Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Data Privacy

Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement

Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.

By Rebecca Leung · August 12, 2026 ·
Table of Contents

Washington’s My Health My Data Act (MHMDA) protects consumer health data that often falls outside HIPAA. For a fintech, the difficult question is not simply whether the company is a financial institution. It is whether a particular item of personal information is governed by and processed pursuant to a statute listed in the MHMDA’s exemptions.

The second precision point is enforcement. The MHMDA uses Washington’s Consumer Protection Act (CPA); it does not establish automatic damages for every affected record.

August 17, 2026 correction

Two broad statements require correction:

  1. GLBA: RCW 19.373.100(2) expressly exempts personal information governed by and collected, used, or disclosed pursuant to GLBA and its implementing regulations. This is a data- and processing-level exemption, not a blanket exemption for every activity of a financial institution.
  2. Private enforcement: RCW 19.373.090 makes a violation an unfair or deceptive act for purposes of the CPA. The Attorney General’s FAQ describes enforcement by the Attorney General and through private action. A private plaintiff proceeds under the CPA and must establish the elements and remedies available there; the statute does not award an automatic fixed amount per consumer.

Why data-level classification matters

A company can hold multiple classes of information under different legal regimes. For example, information collected and used to provide a regulated financial product may be governed by GLBA, while a separate wellness feature, location-derived health inference, or marketing profile may require a different analysis.

Do not label an entire database “GLBA exempt” merely because one product is financial. Instead, record:

  • the data field and source;
  • the consumer and jurisdiction;
  • the processing purpose;
  • the law that governs the collection, use, or disclosure;
  • whether the information remains within that governed use; and
  • any downstream sharing or inference that changes the analysis.

Counsel should confirm close cases. The statutory text places the exemption on qualifying personal information, not on a company name or charter alone.

Use the mixed GLBA and non-GLBA privacy impact assessment to keep that decision attached to the actual field, source, purpose, and recipient. The broader state privacy GLBA exemption guide can help identify the questions, but Washington’s statutory text controls the Washington analysis.

What can be consumer health data

The MHMDA definition is broader than traditional medical records. It can include information linked or reasonably linkable to a consumer that identifies physical or mental health status, including specified categories such as health conditions, treatment, medication, reproductive or sexual health, biometric data, and precise location information that could indicate an attempt to receive health services.

The definition also includes qualifying health information derived or extrapolated from nonhealth information. The Washington Attorney General’s FAQ gives the example of inferences drawn from purchases: an ordinary toiletry purchase is not necessarily health data, but a business’s inference about a person’s health status from purchase data can be.

For fintechs, review features and models that infer or use:

  • medical or pharmacy spending patterns;
  • pregnancy, fertility, disability, or mental-health status;
  • precise location near health-care services;
  • health-related eligibility or risk segments; or
  • health attributes produced from transaction, browsing, or device data.

The presence of one of these features does not answer every coverage question. It triggers a field-level review of definition, linkage, purpose, consent, and exemption.

Core operational obligations for covered processing

For processing within scope, the Act contains requirements concerning:

  • a separate consumer health data privacy policy linked prominently from the homepage;
  • consent for collection or sharing outside what is necessary to provide a consumer-requested product or service;
  • separate, signed authorization for a sale of consumer health data;
  • consumer rights to access, withdraw consent, and delete;
  • processor contracts and instructions;
  • security measures appropriate to the data; and
  • restrictions on geofencing around entities that provide in-person health-care services for specified tracking, collection, or messaging purposes.

The exact rule depends on the actor, data, purpose, and statutory section. Small-business timing differed, but the operative compliance dates for sections 4 through 9 passed in 2024; the geofencing restriction took effect in 2023.

Enforcement through the Washington CPA

RCW 19.373.090 declares that practices covered by the MHMDA are matters vitally affecting the public interest and that a violation is an unfair or deceptive act or practice, and an unfair method of competition, for purposes of the CPA.

That language supports both public and private CPA enforcement, as the Attorney General’s FAQ states. It should not be converted into a claim that the MHMDA created a freestanding cause of action with automatic per-person damages. Private CPA litigation raises additional questions, including injury to business or property, causation, and available remedies under RCW chapter 19.86.

Litigation should be described as allegations

The federal litigation that included Maxwell v. Amazon.com, Inc., No. 2:25-cv-00261-BJR, was consolidated into In re Amazon Ads SDK Litigation, No. 2:25-cv-00252-BJR (W.D. Wash.). Docket allegations and procedural orders are not findings that the defendants violated the MHMDA.

When monitoring cases, distinguish:

  • allegations in a complaint;
  • a motion-to-dismiss ruling;
  • class-certification decisions;
  • settlement terms; and
  • a merits judgment.

Do not cite an allegation as if a court adjudicated the statutory scope.

A defensible fintech workplan

1. Build a health-data overlay on the existing data map

Tag potentially health-related fields, inferences, precise location data, model outputs, and vendor-derived segments. Include data that originates as ordinary transaction or device information but is transformed into a health inference.

2. Record each exemption at the field and use level

For a claimed GLBA exemption, document why the information is governed by and collected, used, or disclosed pursuant to GLBA. Reassess if the use changes or the information moves into a separate product or marketing workflow.

3. Separate processors, sharing, and sales

Map recipients and contractual roles. Do not assume that every transfer is a sale or that every service provider falls outside the Act’s sharing rules. Preserve the legal basis and operational controls for each transfer.

Verify identity, downstream deletion communications, archived-data handling, withdrawal of consent, and retention of a sales authorization where the statute requires it. Test the workflow with the systems that actually hold the data.

5. Review geofencing and SDKs

Inventory location SDKs, advertising integrations, audience tools, and event data around in-person health-care locations. Contract language should match the technical configuration and actual downstream behavior.

Build an Evidence File for Each Coverage Decision

A spreadsheet label such as “health,” “not health,” or “GLBA” is a conclusion, not evidence. For each material data flow, preserve enough information for a reviewer to reconstruct the decision:

Evidence itemWhy it matters
field name, sample value, and data dictionaryshows what the element represents rather than relying on a system label
collection source and consumer interfaceconnects the data to the notice, context, and expectation at collection
processing purpose and model useidentifies whether ordinary data becomes a health inference
governing-law analysisexplains any GLBA or other statutory exclusion at the data-and-use level
recipient and contract rolesupports the processor, sharing, or sale classification
consent or authorization recordproves the scope, action, version, and timing where required
retention and deletion pathshows where copies, derived fields, and downstream transfers are handled
reviewer and review triggermakes the decision accountable when the product or use changes

Do not treat an inference as outside the map because the underlying input looks ordinary. If a transaction, location event, search, or device signal is transformed into a health-related classification, record both the input and the derived output, along with who can use it and for what purpose.

Test Vendors Against the Actual Data Flow

A generic representation that a provider “complies with privacy law” does not establish the firm’s own coverage or consent position. For analytics, advertising, fraud, identity, and location vendors, confirm the fields transmitted, remote configuration, SDK permissions, provider-derived attributes, onward recipients, retention, deletion capability, and use restrictions.

The contract should reflect the role and approved processing. Testing should confirm that production behavior matches the contract. Preserve network or event evidence, configuration exports, deletion-test results, and any discrepancy remediation rather than relying only on a completed questionnaire.

Reassess when a vendor adds a new attribute, inference, audience, integration, or secondary use. A data flow that originally qualified for a GLBA-related purpose may require a new analysis if it moves into an unrelated marketing, wellness, or profiling workflow.

Keep the Consumer Workflow Consistent

Privacy policy, consent, authorization, access, withdrawal, and deletion processes should use the same data inventory and recipient map. If the consumer-facing workflow omits a derived attribute or downstream recipient that appears in the technical map, treat that mismatch as an issue to resolve—not as permission to narrow the map.

Run scenario tests for at least collection, consent withdrawal, deletion, and a vendor termination. Record system results, downstream communications, failed steps, owner, correction date, and retest evidence. These are implementation recommendations; the exact statutory obligation and timing must be mapped to the applicable MHMDA section and the firm’s role.

Bottom line

Washington MHMDA analysis for a fintech is neither “all bank data is exempt” nor “GLBA never matters.” The statute contains an express data-level GLBA exemption, while covered health data outside that exemption may trigger consent, privacy-policy, deletion, contracting, security, and geofencing duties. Enforcement runs through the Washington CPA, with the Attorney General and private plaintiffs using that framework.

Primary and docket sources

This article is for general informational purposes and is not legal advice. Coverage and CPA standing are fact-specific; consult Washington counsel.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does Washington's My Health My Data Act exempt financial institutions covered by GLBA?
The Act does not provide a blanket entity-level exemption for every GLBA-covered financial institution. RCW 19.373.100(2) exempts personal information that is governed by and collected, used, or disclosed pursuant to the Gramm-Leach-Bliley Act and its implementing regulations. A firm must therefore classify the data and processing activity instead of assuming that its institutional status resolves coverage.
Does the MHMDA create a standalone private right of action?
The Act states that a violation is an unfair or deceptive act for purposes of Washington's Consumer Protection Act. The Attorney General says the CPA is enforced by the Attorney General and through private action. A private claimant still proceeds under the CPA and must satisfy the applicable requirements for standing, injury, causation, and remedies; the MHMDA does not promise automatic statutory damages per consumer.
What data can count as consumer health data?
The definition includes personal information linked or reasonably linkable to a consumer that identifies past, present, or future physical or mental health status. It also reaches covered health inferences derived or extrapolated from nonhealth information. Whether a fintech data element qualifies depends on its content, use, linkage, and the statutory exclusions.
What should a fintech do first?
Map data at the field and processing-purpose level. For each item, document whether it is consumer health data, whether the GLBA or another data-level exemption applies, the source and use, disclosures to processors or third parties, consent or authorization, deletion handling, and geofencing controls.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.